发明名称 HIGHLY PARALLEL EVALUATION OF XACML POLICIES
摘要 Techniques for highly parallel evaluation of XACML policies are described herein. In one embodiment, attributes are extracted from a request for accessing a resource including at least one of a user attribute and an environment attribute. Multiple individual searches are concurrently performed, one for each of the extracted attributes, in a policy store having stored therein rules and policies written in XACML, where the rules and policies are optimally stored using a bit vector algorithm. The individual search results associated with the attributes are then combined to generate a single final result using a predetermined policy combination algorithm. It is then determined whether the client is eligible to access the requested resource of the datacenter based on the single final result, including performing a layer-7 access control process, where the network element operates as an application service gateway to the datacenter. Other methods and apparatuses are also described.
申请公布号 US2009288136(A1) 申请公布日期 2009.11.19
申请号 US20080123227 申请日期 2008.05.19
申请人 ROHATI SYSTEMS, INC. 发明人 CHANG DAVID;BAGEPALLI NAGARAJ;NARAYAN HARSHA;PATRA ABHIJIT
分类号 G06F21/00 主分类号 G06F21/00
代理机构 代理人
主权项
地址